Path traversal in lighttpd - #VU14317
Published: August 13, 2018 / Updated: August 13, 2018
lighttpd
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficient check of path names under certain conditions in mod_alias (mod_alias.c). A remote attacker can submit a specially crafted URL and gain access to potentially sensitive information.